U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More
An affidavit filed by the FBI Wednesday alleges a string of hacking operations since 2018. Here’s what to know.
The U.S. federal government has uncovered and disrupted a prolonged Chinese cyber espionage campaign that targeted numerous critical American institutions, including NASA, the Federal Reserve, and the Senate. The Justice Department seized internet domains utilized by two hacking platforms, "QScan" and "QTRouter," operated by a state-sponsored Chinese group. FBI Director Kash Patel stated that the Chinese actors employed techniques to conceal the source of their attacks.
The Chinese state-sponsored group, identified as "QTFY," allegedly targeted various U.S. critical infrastructure and sensitive networks, including the Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The extent of the compromised data remains undetermined, and no arrests or charges have been reported thus far.
China's embassy in Washington, D.C., refuted the accusations, asserting that China is a "firm defender" of cybersecurity. They emphasized that China opposes the U.S. overestimating national security concerns and using them as a means to impose discriminatory restrictions on Chinese companies. The hackers involved reportedly comprised former members of the People's Liberation Army, who leveraged their relationships within the PLA to secure contracts and subcontracts supporting offensive cyber operations.
The hacking campaign, which began in 2018, follows a pattern of U.S. allegations of Chinese state-backed cyber espionage. In 2019, QTFY failed to penetrate NASA's server through a vulnerability in its virtual private network. In 2024, the group conducted cyber intrusions at three unnamed Department of Energy laboratories, the National Institutes of Health, an HHS agency, and a U.S. security device manufacturer.
Additional attempts were detailed in a joint cybersecurity advisory by the FBI, National Security Agency, and U.S. Cyber Command's Cyber National Mission Force.
Notably, the group attempted to breach the U.S. Senate and an American hospital system in March 2026, as well as an unidentified U.S. election system in June 2026, both of which were unsuccessful. Attorney General Todd Blanche emphasized that this issue is a "major national security problem" for the U.S. and that authorities have shared information with the private sector to prevent further attacks.
The announcement comes a month before Chinese President Xi Jinping is scheduled to visit the U.S., amid ongoing trade and technological disputes.
Written by urgent.news from Time's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.